CVE-2023-21402

CRITICAL

Android - Out-of-Bounds Read in MMU_UnmapPages

Title source: llm
STIX 2.1

Description

In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0011
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
google/android
Published Dec 04, 2023
Tracked Since Feb 18, 2026